URLhaus Database

You are currently viewing the URLhaus database entry for http://kizitox.cf/macdonzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1954774
URL: http://kizitox.cf/macdonzx.exe
URL Status:Offline
Host: kizitox.cf
Date added:2022-01-07 08:04:04 UTC
Last online:2022-02-23 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-02-23 06:52:07 UTC to joost[dot]zuurbier{at}verotel[dot]com)
Takedown time:1 month, 16 days, 23 hours, 37 minutes Bad (down since 2022-02-23 07:43:11 UTC)
Tags:AgentTesla link exe Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-21n/aexe eac9e85d242b73ffc2a6b71334b222c1d214b3c3d2372534f7323aeecc3b1006n/aAgentTesla
2022-01-19n/aexe 8e0cb07cbbb9633d69b46022f0ecf114713453b69bcb8972d61a2ff38741a02dn/aAgentTesla
2022-01-18n/aexe 865deee2673a7da5f89031a0dc93bd6ed1f658dbfa63381ea70c8e3460ec0c92n/aAgentTesla
2022-01-14n/aexe 06c80f87ccf8d9b080ac9d8145f111738774ea48fcbc2b4d02ce25aa39dfe938n/a AgentTesla
2022-01-14n/aexe 4ca428445ec6769033f239884895359a1bc523e673b34358adb8bb326799741dn/a AgentTesla
2022-01-13n/aexe 734acbd591b35c3ab42e36ed5b97712ff3d1935a756d9158dbb1fcbaf8b5c1d6n/aAgentTesla
2022-01-13n/aexe 62bc8624b6ed645ddbe1420ca67376863c88e58e347fc8282001a2b9e3330918n/aFormbook
2022-01-12n/aexe 768d2fb5897f1f419aabfbfb7a984e07ff24f6c2261104f90d1840eed8d228dcVirustotal results 20.90% AgentTesla
2022-01-07n/aexe d16bd368a25e14715ec80632e2cded64efd46dd4260f82922b5c64108b2d1437n/aAgentTesla
2022-01-07n/aexe 6821b08cb8ebc1e38504de290856429fed68be2fcaa455e6dde2e6f9926787c1n/aAgentTesla